Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
The vulnerability results from insufficient argument validation (CWE-126 — buffer over-read) when processing IP addresses. An attacker can provide a specially crafted IP address input string, causing data to be read beyond the bounds of an allocated heap buffer. The operation requires no authentication or user interaction, significantly lowering the attack barrier.
An attacker can gain unauthorized access to sensitive data from the OpenVPN process memory (e.g., session keys, configuration data) and cause VPN service failure (denial of service). The combination of high impact on confidentiality and availability results in a CVSS score of 9.1.
Refrain from using alpha/RC versions of branch 2.7 in production environments and apply patches available from the vendor according to references (https://community.openvpn.net/Security%20Announcements/CVE-2025-12106). It is recommended to revert to a stable, supported OpenVPN branch until a fixed version 2.7 is released.
OpenVPN versions 2.7_alpha1 through 2.7_rc1 (inclusive).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HOpenvpn
APPOpenvpn2.6.132.7
Related vulnerabilities
OpenVPN: Wstrzyknięcie danych przez nieoczyszczone wiadomości PUSH_REPLY
OpenVPN dla Windows — ładowanie wtyczek z dowolnego katalogu
Use-after-free w OpenVPN 2.6.0–2.6.6 umożliwiający RCE
OpenVPN: Authentication Bypass przez wtyczki z odroczoną autoryzacją
OpenVPN: cross-protocol scripting przez interfejs zarządzania TCP